Uploaded August 2025 | Updated September 2026, 7 hours ago
Tomo Ito (JPCERT Coordination Center, JP), Justin Murphy (DHS/CISA, US)
Working on CVD at JPCERT/CC for 9 years, Tomo currently leads the Global CVD project of the organization, which aims to contribute to the global CVD ecosystem stability through collaborations with the stakeholders from different parts of the world.
Justin Murphy is a Vulnerability Analyst with the Cybersecurity and Infrastructure Security Agency (CISA). He helps to coordinate the remediation, mitigation, and public disclosure of newly identified cybersecurity vulnerabilities in products and services with affected vendor(s), ranging from industrial control systems (ICS), operational technology (OT), medical devices, and traditional information technology (IT) vulnerabilities. Justin is involved with many other vulnerability management related efforts, including CISA's Software Bill of Materials (SBOM) and Vulnerability Exploitability eXchange (VEX) work, and he serves as a co-chair for the OASIS Common Security Advisory Framework (CSAF) and OpenEoX Technical Committees. Justin is also the co-founder of the Global Community of Practice on Coordinated Vulnerability Disclosure (Global CVD-COP). Justin is a former high school mathematics teacher turned cybersecurity professional and has a M.Sc. in Computer Science from Tennessee Technological University, and a B.Sc. degree in Statistics from the University of Tennessee (Knoxville).
--
As global cyber threats become increasingly sophisticated and widespread, Coordinated Vulnerability Disclosure (CVD) serves as an essential, structured approach for timely and effective communication of vulnerability information among the affected stakeholders. The recently established Global Community of Practice on CVD (CVD-COP) is an important initiative aimed at encouraging collaboration among governmental entities and national CERTs in their roles as third-party CVD coordinators. This presentation will explore the motivations behind the CVD-COP's formation, emphasizing the critical need for CVD as a good global practice and an essential risk reduction activity.We will outline the community's key activities, including developing best practices and training materials, facilitating knowledge and experience sharing, and promoting international cooperation among stakeholders. These efforts aim to establish harmonization and enhance the effectiveness of CVD across the globe.The presentation will also review the challenges faced by the CVD-COP, such as varying levels of understanding among participants and the complexities of different governance criteria. Addressing these issues is crucial for achieving the community's objectives and realizing the benefits of harmonization for CVD practices globally. The presentation will facilitate an interactive discussion, inviting audience input on how the community can optimize its support for the vulnerability management ecosystem. By inviting participants to share their insights and experiences, we hope to identify strategies that can strengthen the CVD-COP's effectiveness and foster a collaboration among global stakeholders, including security researchers, vendors, and downstream users, ultimately promoting a more secure vulnerability management ecosystem.
Tomo Ito (JPCERT Coordination Center, JP), Justin Murphy (DHS/CISA, US)
Working on CVD at JPCERT/CC for 9 years, Tomo currently leads the Global CVD project of the organization, which aims to contribute to the global CVD ecosystem stability through collaborations with the stakeholders from different parts of the world.
Justin Murphy is a Vulnerability Analyst with the Cybersecurity and Infrastructure Security Agency (CISA). He helps to coordinate the remediation, mitigation, and public disclosure of newly identified cybersecurity vulnerabilities in products and services with affected vendor(s), ranging from industrial control systems (ICS), operational technology (OT), medical devices, and traditional information technology (IT) vulnerabilities. Justin is involved with many other vulnerability management related efforts, including CISA's Software Bill of Materials (SBOM) and Vulnerability Exploitability eXchange (VEX) work, and he serves as a co-chair for the OASIS Common Security Advisory Framework (CSAF) and OpenEoX Technical Committees. Justin is also the co-founder of the Global Community of Practice on Coordinated Vulnerability Disclosure (Global CVD-COP). Justin is a former high school mathematics teacher turned cybersecurity professional and has a M.Sc. in Computer Science from Tennessee Technological University, and a B.Sc. degree in Statistics from the University of Tennessee (Knoxville).
--
As global cyber threats become increasingly sophisticated and widespread, Coordinated Vulnerability Disclosure (CVD) serves as an essential, structured approach for timely and effective communication of vulnerability information among the affected stakeholders. The recently established Global Community of Practice on CVD (CVD-COP) is an important initiative aimed at encouraging collaboration among governmental entities and national CERTs in their roles as third-party CVD coordinators. This presentation will explore the motivations behind the CVD-COP's formation, emphasizing the critical need for CVD as a good global practice and an essential risk reduction activity.We will outline the community's key activities, including developing best practices and training materials, facilitating knowledge and experience sharing, and promoting international cooperation among stakeholders. These efforts aim to establish harmonization and enhance the effectiveness of CVD across the globe.The presentation will also review the challenges faced by the CVD-COP, such as varying levels of understanding among participants and the complexities of different governance criteria. Addressing these issues is crucial for achieving the community's objectives and realizing the benefits of harmonization for CVD practices globally. The presentation will facilitate an interactive discussion, inviting audience input on how the community can optimize its support for the vulnerability management ecosystem. By inviting participants to share their insights and experiences, we hope to identify strategies that can strengthen the CVD-COP's effectiveness and foster a collaboration among global stakeholders, including security researchers, vendors, and downstream users, ultimately promoting a more secure vulnerability management ecosystem.










